Redhat
redhat
5,674 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,674)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 6Cloudforms 3.0.1 Management Engine Cloudforms 3.0.2 Management EngineCloudforms 3.0.3 Management Engine+3 moreMay 6, 2026 Oct 6, 2014 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Red Hat CloudForms 3.1 Management Engine (CFME) before 5.3 allows remote authenticated users to access sensitive controllers and actions via a direct HTTP or HTTPS request. |
Red Hat Conga 0.12.2 allows remote attackers to obtain sensitive information via a crafted request to the (1) homebase, (2) cluster, (3) storage, (4) portal_skins/custom, or (5) logs Luci extension. |
3Canonical OpenstackRedhat3Keystone OpenstackUbuntu LinuxMay 6, 2026 Oct 2, 2014 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated...Show more |
4Debian FedoraprojectLibvncserver+1 more5Debian Linux Enterprise Linux Server AusEnterprise Linux Server Eus+2 moreMay 6, 2026 Sep 30, 2014 N/A· v4 N/A· v3 6.5 MEDIUM· v2 Multiple stack-based buffer overflows in the File Transfer feature in rfbserver.c in LibVNCServer 0.9.9 and earlier allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary cod...Show more |
5Debian FedoraprojectLibvncserver+2 more6Debian Linux Enterprise Linux Server AusEnterprise Linux Server Eus+3 moreMay 6, 2026 Sep 30, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 Integer overflow in the MallocFrameBuffer function in vncviewer.c in LibVNCServer 0.9.9 and earlier allows remote VNC servers to cause a denial of service (crash) and possibly execute arbitrary code via an advertisement...Show more |
ReflectionHelper (org.hibernate.validator.util.ReflectionHelper) in Hibernate Validator 4.1.0 before 4.2.1, 4.3.x before 4.3.2, and 5.x before 5.1.2 allows attackers to bypass Java Security Manager (JSM) restrictions and...Show more |
2Jboss Redhat2Jboss Data Virtualization TeiidMay 6, 2026 Sep 30, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Teiid before 8.4.3 and before 8.7 and Red Hat JBoss Data Virtualization 6.0.0 before patch 3 allows remote attackers to read arbitrary files via a crafted request to a REST endpoint, related to an XML External Entity (XX...Show more |
3Canonical LinuxRedhat6Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Server+3 moreMay 6, 2026 Sep 28, 2014 N/A· v4 N/A· v3 7.8 HIGH· v2 The SMB2_tcon function in fs/cifs/smb2pdu.c in the Linux kernel before 3.16.3 allows remote CIFS servers to cause a denial of service (NULL pointer dereference and client system crash) or possibly have unspecified other...Show more |
17Apple AristaCanonical+14 more74Arx Firmware BashBig Ip Access Policy Manager+71 moreApr 22, 2026 Sep 25, 2014 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown oth...Show more |
17Apple AristaCanonical+14 more74Arx Firmware BashBig Ip Access Policy Manager+71 moreApr 22, 2026 Sep 24, 2014 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vec...Show more |
2Redhat Suse5Manager Manager ServerSatellite+2 moreMay 6, 2026 Sep 22, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in spacewalk-java 1.2.39, 1.7.54, and 2.0.2 in Spacewalk and Red Hat Network (RHN) Satellite 5.4 through 5.6 allows remote attackers to inject arbitrary web script or HTML via a c...Show more |
Session fixation vulnerability in the web admin interface in oVirt 3.4.0 and earlier allows remote attackers to hijack web sessions via unspecified vectors. |
3Apache LibreofficeRedhat5Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+2 moreMay 6, 2026 Aug 27, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The OLE preview generation in Apache OpenOffice before 4.1.1 and OpenOffice.org (OOo) might allow remote attackers to embed arbitrary data into documents via crafted OLE objects. |
2Fedoraproject Redhat3389 Directory Server Directory ServerEnterprise LinuxMay 6, 2026 Aug 21, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Red Hat Directory Server 8 and 389 Directory Server, when debugging is enabled, allows remote attackers to obtain sensitive replicated metadata by searching the directory. |
3Canonical OpenstackRedhat6Neutron OpenstackOslo+3 moreMay 6, 2026 Aug 19, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authe...Show more |
5Apache AppleCanonical+2 more9Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Server+6 moreMay 6, 2026 Aug 19, 2014 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier for remote servers to obtain the credent...Show more |
1Redhat 2Jboss Enterprise Application Platform ResteasyMay 6, 2026 Aug 19, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 RESTEasy 2.3.1 before 2.3.8.SP2 and 3.x before 3.0.9, as used in Red Hat JBoss Enterprise Application Platform (EAP) 6.3.0, does not disable external entities when the resteasy.document.expand.entity.references parameter...Show more |
1Redhat 1Jboss Enterprise Application Platform May 6, 2026 Aug 19, 2014 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The isCallerInRole function in SimpleSecurityManager in JBoss Application Server (AS) 7, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.3.0, does not properly check caller roles, which allows remote a...Show more |
1Redhat 1Jboss Enterprise Application Platform May 6, 2026 Aug 19, 2014 N/A· v4 N/A· v3 5.5 MEDIUM· v2 The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) 6.2.0 and 6.3.0, does not properly enforce the method level restrictions for outbound messages, which a...Show more |
3Debian MitRedhat6Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+3 moreMay 6, 2026 Aug 14, 2014 N/A· v4 N/A· v3 7.8 HIGH· v2 The acc_ctx_cont function in the SPNEGO acceptor in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.5.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (NULL pointer deref...Show more |